HELP
TABLE OF CONTENTS

VPN>Configure>Manual Key

You can configure the Manual Key SA for VPN Clients or SonicWALL to SonicWALL VPN connections.

Configuring Manual Key for VPN Clients

Note! The SonicWALL Global VPN Client does not use Manual Key.

  1. Select Add New SA from the Security Association menu.

  2. Select Manual Key from the IPSec Keying Mode menu.

  3. Enter a descriptive name that identifies the VPN client in the Name field, such as the client’s location or name.

  4. Make sure the Disable This SA box is unchecked to enable this VPN policy.

  5. Enter "0.0.0.0" in the IPSec Gateway Name or Address field.

Security Policy

  1. Define an Incoming SPI and an Outgoing SPI. The SPIs are hexadecimal (0123456789abcedf) and can range from 3 to 8 characters in length.

Alert! Each Security Association must have unique SPIs; no two Security Associations can share the same SPIs. However, each Security Association Incoming SPI can be the same as the Outgoing SPI.

  1. Select Encrypt and Authenticate (ESP 3DES HMAC MD5) from the Encryption Method menu.

Alert! It is important to remember the Encryption Method selected as you need to select the same parameters in the VPN Client configuration.

  1. Enter a 16 character hexadecimal encryption key in the Encryption Key field or use the default value. This encryption key is used to configure the remote SonicWALL client's encryption key, therefore, write it down to use when configuring the client.

  2. Enter a 32 character hexadecimal authentication key in the Authentication Key field or use the default value. Write down the key to use while configuring the client settings.

Tip! Valid hexadecimal characters include 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, a,b, c, d, e, and f. 1234567890abcdef is an example of a valid DES or ARCFour encryption key. If you enter an incorrect encryption key, an error message is displayed at the bottom of the browser window.

Destination Networks

  1. Select Use this SA as the default route for all Internet traffic if all remote VPN connections access the Internet through this SA. You can only configure one SA to use this feature. If you do not select this feature, go to Step 10.

  2. Click Add New Network to enter the destination network addresses. Clicking Add New Network automatically updates the VPN configuration and opens the VPN Destination Network window.

  3. Enter "0.0.0.0" in the Range Start, Range End, and Destination Subnet Mask for NetBIOS broadcast fields.

  4. Click Update to add the remote network and close the VPN Destination Network window. Once the SonicWALL has been updated, a message confirming the update is displayed at the bottom of the browser window.

Configuring Manual Key for SonicWALL to SonicWALL VPN Connections

VPN between two SonicWALLs allows users to securely access files and applications at remote locations. The first step to set up a VPN between two SonicWALLs is creating corresponding Security Associations (SAs). The instructions below describe how to create an SA using Manual Key followed by an example illustrating a VPN tunnel between two SonicWALLs.

Configuring the First SonicWALL

  1. Select -Add New SA- from the Security Association menu.

  2. Select Manual Key from the IPSec Keying Mode menu.

  3. Enter a descriptive name for the Security Association, such as "Chicago Office" or "Remote Management", in the Name field.

  4. Enter the IP address of the remote VPN gateway in the IPSec Gateway Address field. This must be a valid IP address and is the remote VPN gateway NAT Public Address if NAT is enabled. Enter "0.0.0.0" if the remote VPN gateway has a dynamic IP address.

  5. Define an SPI (Security Parameter Index) that t!he remote SonicWALL uses to identify the Security Association in the Incoming SPI field.

  6. Define an SPI that the local SonicWALL uses to identify the Security Association in the Outgoing SPI field. SPIs should range from 3 to 8 characters in length and include only hexadecimal characters.

Alert! Each Security Association must have unique SPIs; no two Security Associations can share the same SPIs. However, each Security Association Incoming SPI can be the same as the Outgoing SPI.

  1. Select an encryption algorithm from the Encryption Method menu. Enter a 16-character hexadecimal key in the Encryption Key field if you are using DES or ARCFour encryption. Enter a 48-character hexadecimal key if you are using Triple DES encryption. This encryption key must match the remote SonicWALL's encryption key.

    When a new SA is created, a 48-character key is automatically generated in the Encryption Key field. This can be used as a valid key for Triple DES. If this key is used, it must also be entered in the Encryption Key field in the remote SonicWALL. If Tunnel Only (ESP NULL) or Authenticate (AH MD5) is used, the Encryption Key field is ignored.

  2. Enter a 32-character, hexadecimal key in the Authentication Key field.

    When a new SA is created, a 32-character key is automatically generated in the Authentication Key field. This key can be used as a valid key. If this key is used, it must also be entered in the Authentication Key field in the remote SonicWALL. If authentication is not used, this field is ignored.

  3. Click Add New Network to enter the destination network addresses. Clicking Add New Network automatically updates the VPN configuration and opens the VPN Destination Network window.

  4. Enter the beginning IP address of the remote network address range in the Range Start field. If NAT is enabled on the remote SonicWALL, enter a private LAN IP address. Enter "0.0.0.0" to accept all remote SonicWALLs with matching encryption and authentication keys.

  5. Enter the ending IP address of the remote network's address range in the Range End field. If NAT is enabled on the remote SonicWALL, enter a private LAN IP address. Enter "0.0.0.0" to accept all remote SonicWALLs with matching encryption and authentication keys.

  6. Enter the remote network subnet mask in the Destination Subnet Mask for NetBIOS broadcast field if Enable Windows Networking (NetBIOS) Broadcast is selected. Otherwise, enter "0.0.0.0" in the field.

  7. Click Update to add the remote network and close the VPN Destination Network window. Once the SonicWALL has been updated, a message confirming the update is displayed at the bottom of the browser window.

  8. Click Advanced Settings and check the boxes that apply to your SA:
  1. Click OK to close the Advanced Settings window.

  2. Click Update to update the SonicWALL.

Configuring the Second SonicWALL Appliance

To configure the second SonicWALL appliance, follow the same configuration steps as the first SonicWALL. You must enter the same SPIs and Encryption keys as the first SonicWALL appliance into the settings of the second SonicWALL appliance.

Example of Manual Key Configuration for Two SonicWALLs

Widgit, Inc. wants to connect their main office with a branch office on the East Coast. Using a SonicWALL PRO 300 and a TELE3, they can configure a secure VPN tunnel between the two sites. The main office has the following network settings:

The remote office has the following network settings:

Configuring the SonicWALL at the Main Office

To configure the main office PRO 300, use the following steps:

  1. Configure the network settings for the firewall using the Network tab located in the General section.

  2. Click Update and restart the SonicWALL if necessary.

  3. Click VPN, then the Configure tab.

  4. Create a name for the main office SA, for example, Main Office.

  5. Enter the remote office WAN IP address for the IPSec Gateway Address.

  6. Create an Incoming SPI using alphanumeric characters.

  7. Create an Outgoing SPI using alphanumeric characters.

  8. Select Strong Encrypt (ESP 3DES) as the Encryption Method.

  9. Write the Encryption Key down or use cut and paste to copy it to a Notepad window.

  10. Click Add New Network. Enter the IP address, “192.168.22.1” in the Range Start field. Enter the IP address, “192.168.22.254” in the Range End field. This Range End value is appropriate even if NetBIOS broadcast support is enabled. Leave the subnet mask field blank.

  11. Click Update.

  12. Click Advanced Settings and select the features that apply to the SA.
  1. Click OK, and then click Update.

Configuring the Remote SonicWALL

To configure the remote SonicWALL, use the following steps:

  1. Configure the network settings for the firewall using the Network tab located in the General section.

  2. Click Update and restart the SonicWALL if necessary.

  3. Click VPN, then the Configure tab.

  4. Create a name for the remote office SA, for example, Remote Office.

  5. Enter the main office WAN IP address for the IPSec Gateway Address.

  6. Enter the Outgoing SPI of the main office in the Incoming SPI field.

  7. Enter the Incoming SPI of the main office in the Outgoing SPI field.

  8. Select Strong Encrypt (ESP 3DES) as the Encryption Method.

  9. Enter the Encryption Key from the Main Office configuration.

  10. Click Add New Network. Enter the IP address, “192.168.11.1” in the Range Start field. Enter the IP address, “192.168.11.254” in the Range End field. This Range End value is appropriate even if NetBIOS broadcast support is enabled. Leave the subnet mask field blank.

  11. Click Update.

  12. Click Advanced Settings and select the features that apply to the SA.
  1. Click OK, then click Update.